import { timingSafeEqual } from "node:crypto"; /** * Constant-time string comparison. `timingSafeEqual` throws on mismatched * buffer lengths, which would itself leak length via which branch throws - * so a length mismatch is treated as a plain (also constant-time-irrelevant, * since it never reaches the byte comparison) false rather than propagating. */ export function timingSafeStringEqual(a: string, b: string): boolean { const bufA = Buffer.from(a); const bufB = Buffer.from(b); if (bufA.length !== bufB.length) return false; return timingSafeEqual(bufA, bufB); }